Vulnslist

find the latest Cisco vulnerabilities

Cisco Ultra Services Platform Information Disclosure Vulnerability

cisco-sa-20170607-usp2 · Medium · Published · Updated

A vulnerability in the ConfD server in Cisco Ultra Services Platform could allow an authenticated, local attacker to view sensitive information. The vulnerability is due to insufficient protection of sensitive files on the system. An attacker could exploit this vulnerability by logging in to the ConfD server. An exploit could allow an unprivileged user to access and view sensitive information in the system. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-usp2

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2017-6695
Cisco Bug IDsCSCvd29398
CVSS ScoreBase 5.5
Base 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Ultra Services Platform

Related Products

Product CVE Evidence
Cisco Ultra Services Platform CVE-2017-6695 Cisco OpenVuln